Detection catalogue
Explore published rules with transparent provenance, licensing, and ATT&CK mappings.
- 11,263
- detections
Showing 30 of 11,263
Identifies the first time, in a historical window, a host runs AzCopy copy or sync to Azure Blob, Data Lake, or File storage, or starts Azure Storage Explorer. These Microsoft utilities are legitimate data-transfer tools; ransomware and cloud-ransomware operators drop portable copies and use SAS-authenticated jobs to pull data from victim storage and push it to attacker-controlled accounts.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 11, 2026
- Upstream
- 7265f4fa-4839-4399-924c-a91f1e45d76c
Specially crafted DNS requests can manipulate a known overflow vulnerability in some Windows DNS servers, resulting in Remote Code Execution (RCE) or a Denial of Service (DoS) from crashing the service.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 11, 2026
- Upstream
- 11013227-0301-4a8c-b150-4db924484475
This rule detects network events that may indicate the use of RPC traffic to the Internet. RPC is commonly used by system administrators to remotely control a system for maintenance or to use shared resources. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 11, 2026
- Upstream
- 32923416-763a-4531-bb35-f33b9232ecdb
This rule identifies a potential SYN-Based port scan. A SYN port scan is a technique employed by attackers to scan a target network for open ports by sending SYN packets to multiple ports and observing the response. Attackers use this method to identify potential entry points or services that may be vulnerable to exploitation, allowing them to launch targeted attacks or gain unauthorized access to the system or network, compromising its security and potentially leading to data breaches or
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 11, 2026
- Upstream
- bbaa96b9-f36c-4898-ace2-581acb00a409
This rule identifies a potential port scan from an internal IP address. A port scan is a method utilized by attackers to systematically scan a target system for open ports, allowing them to identify available services and potential vulnerabilities. By mapping out the open ports, attackers can gather critical information to plan and execute targeted attacks, gaining unauthorized access, compromising security, and potentially leading to data breaches, unauthorized control, or further exploitation
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 11, 2026
- Upstream
- 0171f283-ade7-4f87-9521-ac346c68cc9b
This rule identifies outbound IPSEC NAT Traversal (NAT-T) traffic to an external destination IP that was not observed during the previous 5 days. IPSEC is a VPN technology that allows one system to talk to another using encrypted tunnels. NAT Traversal encapsulates IPSEC ESP traffic in UDP and, once a NAT device is detected, both peers float to UDP port 4500 for the tunnel data channel.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 11, 2026
- Upstream
- a9cb3641-ff4b-4cdc-a063-b4b8d02a67c7
This rule detects network events that may indicate the use of Telnet traffic. Telnet is commonly used by system administrators to remotely control older or embedded systems using the command line shell. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector. As a plain-text protocol, it may also expose usernames and passwords to anyone capable of observing the traffic.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 11, 2026
- Upstream
- 34fde489-94b0-4500-a76f-b8a157cf9269
Identifies a Microsoft Entra ID device registration by the same user within 15 minutes of a phishing-resistant, device-bound credential (Windows Hello for Business, FIDO2 security key, or passkey) signing in with no device identifier. In the "borrowing Windows Hello keys" technique, an adversary reuses a WHfB/NGC key or passkey away from its bound device to mint device-agnostic tokens, then uses those tokens to register an attacker-controlled device and obtain a Primary Refresh Token (PRT) for
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 11, 2026
- Upstream
- 62848597-595c-4cc3-8d24-6c47a5fee9a9
Identifies the first-seen registration of a Windows Hello for Business (WHfB) credential for a Microsoft Entra ID user from a given source ASN in a tenant, based on a prefixed historic window. Enrollment is commonly part of legitimate onboarding or passwordless rollout and is not inherently malicious. Adversaries who have obtained a token that satisfies fresh (NGC) multi-factor authentication, for example by borrowing an existing WHfB key or passkey, can also enroll their own WHfB credential to
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 11, 2026
- Upstream
- 8c6f8cca-f730-4cdd-93a7-d65f087a4116
Identifies a Microsoft Entra ID sign-in that is satisfied by a phishing-resistant, device-bound credential (Windows Hello for Business, FIDO2 security key, or passkey) while carrying no device identifier. Windows Hello for Business (WHfB) and passkey credentials are bound to a device's TPM, so a genuine sign-in with one of these methods is normally accompanied by the registered device it lives on. A WHfB or passkey assertion that authenticates with an empty `device_detail.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 11, 2026
- Upstream
- 763b0a74-2961-4396-bb4b-8cd850e1ebe4
Detects a first-party FOCI tooling client (Azure CLI, PowerShell, VS Code, Graph CLI, Azure AD PowerShell, or Visual Studio) redeeming a device-bound Primary Refresh Token (PRT) for Microsoft Graph, SharePoint/OneDrive, or Exchange Online from a source IP that has not been seen with that deviceid. Replay events are limited to compliant or Intune-managed devices.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 11, 2026
- Upstream
- 9e8d9bb5-6d3a-4431-a0d0-8d0475e726a4
Detects a first-party FOCI tooling client (Azure CLI, PowerShell, VS Code, Graph CLI, Azure AD PowerShell, or Visual Studio) redeeming a device-bound Primary Refresh Token (PRT) for Microsoft Graph, SharePoint/OneDrive, or Exchange Online from an IP that is not among that user and device's Windows Sign-In or WAM addresses. Replay events are limited to compliant or Intune-managed devices: the stolen cookie keeps the workstation deviceid, so compliant-device Conditional Access can succeed off-box.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 11, 2026
- Upstream
- 6a9fdaab-b50f-408d-b4da-54719f256d41
This detection correlates Suricata alerts with Elastic Defend network events to identify the source process performing the network activity.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 11, 2026
- Upstream
- 9edd000e-cbd1-4d6a-be72-2197b5625a05
This query lists DNS queries not found in the top 1 million queries in the past 14 days. Please note: To enhance performance, this query uses summarized data if available. The Hunting query also depends on the "**DNSEssentialsCustomParser**" Parser, so please make sure it is installed and configured before you use this Hunting query.
- Licence
- MIT License
- Published
- Sep 10, 2026
- Upstream
- 83e70a34-d96f-419d-815b-43d1499e88ed
Checks for an anomalous increase in DNS activity per client in the last 24 hours as compared to the last 14 days. Please note: To enhance performance, this query uses summarized data if available. The Hunting query also depends on the "**DNSEssentialsCustomParser**" Parser, so please make sure it is installed and configured before you use this Hunting query.
- Licence
- MIT License
- Published
- Sep 10, 2026
- Upstream
- 50f0cdfb-8b01-4eca-823d-2bbe6b8a5b95
This rule makes use of the series decompose anomaly method to detect clients with a high NXDomain response count, which could be indicative of a DGA (cycling through possible C2 domains where most C2s are not live). An alert is generated when new IP address DNS activity is identified as an outlier when compared to the baseline, indicating a recurring pattern. It utilizes [ASIM](https://aka.ms/AboutASIM) normalization and is applied to any source that supports the ASIM DNS schema.
- Licence
- MIT License
- Published
- Sep 10, 2026
- Upstream
- 01191239-274e-43c9-b154-3a042692af06
This rule makes use of the series decompose anomaly method to generate an alert when multiple clients report errors for the same DNS query. This rule monitors DNS traffic over a period of 14 days to detect possible similar C2 communication originating from different clients. It utilizes [ASIM](https://aka.ms/AboutASIM) normalization and is applied to any source that supports the ASIM DNS schema.
- Licence
- MIT License
- Published
- Sep 10, 2026
- Upstream
- cf687598-5a2c-46f8-81c8-06b15ed489b1
This rule makes use of the series decompose anomaly method to generate an alert when client requests excessive amount of DNS queries to non-existent domains. This helps in identifying possible C2 communications. It utilizes [ASIM](https://aka.ms/AboutASIM) normalization and is applied to any source that supports the ASIM DNS schema. The rule also depends on the "**DNSEssentialsCustomParser**" Parser, so please make sure it is installed and configured before you use this Rule.
- Licence
- MIT License
- Published
- Sep 10, 2026
- Upstream
- 02f23312-1a33-4390-8b80-f7cd4df4dea0
Identifies when an excessive number of files are downloaded from OneDrive or SharePoint by an authorized user or application in a short period of time. This may indicate a potential data exfiltration event, especially if the downloads are performed using OAuth authentication which could suggest an OAuth phishing attack such as Device Code Authentication phishing.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 10, 2026
- Upstream
- 0e524fa6-eed3-11ef-82b4-f661ea17fbce
The following analytic correlates modifications to the Windows RunMRU registry key with clipboard content changes initiated by browsers. It aims to detect ClickFix scenarios in which commands copied from a browser are subsequently executed on the Windows system through the Run dialog box.
- Licence
- Apache License 2.0
- Written by
- Onur Mustafa Erdogan +1
- Published
- Sep 9, 2026
- Upstream
- 5d1fdbcb-5ed9-4190-85c8-7f9026450a0b
An adversary can establish persistence by installing a new launch agent that executes at login by using launchd or launchctl to load a plist into the appropriate directories.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 9, 2026
- Upstream
- 082e3f8c-6f80-485c-91eb-5b112cb79b28
Detects when a scripting interpreter makes an outbound network connection to an Ethereum blockchain endpoint for command and control purposes. Adversaries may leverage Ethereum blockchain infrastructure as a covert C2 channel to receive commands and exfiltrate data, as observed in campaigns like SleepyDuck malware.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 9, 2026
- Upstream
- bba8c7d1-172b-435d-9034-02ed9289c628
Detects when curl or nscurl is spawned by a shell or osascript to make a JSON-RPC request to a blockchain endpoint for command and control purposes. Adversaries may leverage blockchain smart contracts as a covert C2 channel to retrieve commands or payload staging information, as observed in ClickFix campaigns.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 9, 2026
- Upstream
- 54285d96-2b7c-4345-890e-3c40e173f099
Detects when account-level email sending is explicitly enabled in Amazon SES, via the v1 UpdateAccountSendingEnabled API with Enabled: true or the v2 PutAccountSendingAttributes API with SendingEnabled: true. Account-level sending is commonly paused by an administrator, or by automation wired to CloudWatch reputation alarms when bounce or complaint rates rise.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 9, 2026
- Upstream
- e3f4a5b6-c7d8-9012-cdef-34567890abcd
Detects when AWS Security Hub is disabled in a region. Security Hub aggregates security findings from AWS services (GuardDuty, Inspector, Macie, IAM Access Analyzer) and third-party tools into a single pane of glass. Disabling it suppresses centralized finding aggregation and compliance checks, removing visibility into threats across the account. This action is a documented pre-ransomware and pre-exfiltration defense evasion technique.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 9, 2026
- Upstream
- c8a2d4f6-1b3e-4a7c-9d5f-8e0b2c6a4d1e
Identifies failed authentication attempts against the AWS Management Console root user from the same source IP address targeting multiple AWS accounts. Password spraying uses few attempts per target across many accounts to avoid lockout, making per-account volume an unreliable signal. This rule detects the cross-account breadth pattern: a single source IP generating root ConsoleLogin failures across two or more distinct AWS accounts.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 9, 2026
- Upstream
- 171d3cdd-0c04-47c2-b392-65719284ae25
The following analytic identifies suspicious PowerShell execution using Script Block Logging (EventCode 4104). It leverages specific patterns and keywords within the ScriptBlockText field to detect potentially malicious activities. This detection is significant for SOC analysts as PowerShell is commonly used by attackers for various malicious purposes, including code execution, privilege escalation, and persistence.
- Licence
- Apache License 2.0
- Written by
- Michael Haag +1
- Published
- Sep 8, 2026
- Upstream
- d6f2b006-0041-11ec-8885-acde48001122
Identifies a match in Syslog data from any malicious URL indicator ingested from PRODAFT USTA IoC Threat Intelligence (SourceSystem starting with "PRODAFT USTA").
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- 99ae4d06-d352-4926-a1d7-9c28e25b1313
Identifies a match in CommonSecurityLog data from any file-hash indicator ingested from PRODAFT USTA IoC Threat Intelligence (SourceSystem starting with "PRODAFT USTA").
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- 9c2cef4e-c3a3-4be9-8923-a2f820d4face
Identifies a match in DnsEvents from any domain-name indicator ingested from PRODAFT USTA IoC Threat Intelligence (SourceSystem starting with "PRODAFT USTA").
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- c6f85aff-4ef0-4fde-b90e-e0ba1a9c3df6
Entra ID Device-Bound PRT Replay via First-Party App from Unusual IP
Detects a first-party FOCI tooling client (Azure CLI, PowerShell, VS Code, Graph CLI, Azure AD PowerShell, or Visual Studio) redeeming a device-bound Primary Refresh Token (PRT) for Microsoft Graph, SharePoint/OneDrive, or Exchange Online from an IP that is not among that user and device's Windows Sign-In or WAM addresses. Replay events are limited to compliant or Intune-managed devices: the stolen cookie keeps the workstation deviceid, so compliant-device Conditional Access can succeed off-box.
ATT&CK coverage
What the source says
What fires this without an attack behind it
- A user running Azure CLI, Azure PowerShell, VS Code, Graph CLI, or Visual Studio on a jump host, Cloud Shell, or VPN egress that differs from the workstation's Windows Sign-In IP can match if that activity still presents a compliant or managed workstation deviceid. Validate whether the Graph client ran on the enrolled device before treating the event as cookie theft.
- Microsoft Teams, Microsoft Office, OneDrive SyncEngine, Microsoft Authentication Broker, Outlook Mobile, Bing, Azure Portal, ADIbizaUX, and Office 365 Management are omitted. The rest of the Secureworks known-foci-clients.csv family (Edge, OneDrive, Intune Company Portal, Windows Search, Authenticator, SharePoint, Planner, Power BI, and similar) is omitted for the same reason: routine workstation or mobile Graph whose Microsoft 365 egress often differs from the Windows Sign-In IP without cookie theft. Hunt those app_ids separately if harvest is already confirmed.
- Split-tunnel or dual-homed devices may present different egress IPs for WAM versus Azure CLI. Confirm both IPs belong to the same physical device before raising severity.
References
- https://github.com/Gerenios/AADInternals
Tool · github.com
5 detections cite this - https://github.com/armadin-public/PRTremote
Tool · github.com
2 detections cite this - https://github.com/dmcxblue/ANIMO/blob/master/helpers/scripts/GrabTokenAzureAD/PrtExtractor.cs
Tool · github.com
3 detections cite this - https://github.com/rvrsh3ll/TokenTactics
Tool · github.com
3 detections cite this - https://www.armadin.com/blog-posts/prtremote-extract-prt-cookies-remotely-with-interactivetoken-scheduled-task
Unclassified · www.armadin.com
Tagged by the source as
Detection logic
Its licence does not clear it for publishing here
Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.